CVE: CVE-2005-2029

Export to Word

amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

Threat-Mapped Scoring

Score: 3.0

Priority: P2 - Serious (High)

EPSS

Score: 0.00654
Percentile: 0.69979

CVSS Scoring

CVSS v2 Score: 7.5

Severity:

Affected Products

← Back to Home